CVE-2012-6636

Scores

EPSS

0.771medium77.1%
0%20%40%60%80%100%

Percentile: 77.1%

CVSS

6.8medium2.0
0246810

CVSS Score: 6.8/10

All CVSS Scores

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvdubuntu

CWEs

CWE-264

Exploits

Exploit ID: 41675

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41675

Vulnerable Software (13)

Type: Configuration

Product: cordova-ubuntu

Operating System: ubuntu trusty 14.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu

Operating System: ubuntu utopic 14.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu

Operating System: ubuntu vivid 15.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu

Operating System: ubuntu wily 15.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu artful 17.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu trusty 14.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu utopic 14.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu vivid 15.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu wily 15.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu xenial 16.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu yakkety 16.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: cordova-ubuntu-3.4

Operating System: ubuntu zesty 17.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Vendor: *

Product: android_api

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:google:android_api:*:*:*:*:*:*:*:*",      "versionEndIncluding": "16.0",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:googl...

Source: nvd

End of list